Skip to main content

Overview

The Overview tab is the first page of Intelligence. It answers three questions at a glance: what in your environment matches threat intel right now, whether your intel feeds are healthy, and which threats are relevant to you.

Beta

Intelligence is in beta, and access is by request. It may not be enabled for your organization.

Open the Overview​

Click Intelligence in the navigation menu. The Overview tab opens first. The numbers cover the scope you picked in the Scope selector.

Pick a time range​

The menu at the top right sets the time range for matches: Last 24 hours (the default), Last 7 days or Last 30 days. The range is kept in the page address, so a link you share opens with the same range.

Headline tiles​

TileWhat it showsClick to open
MatchesHow many times an indicator from your intel was seen in your data during the time range, and how many of those were high confidence.Indicators, filtered to sighted indicators
Active indicatorsIndicators that are currently active across the feeds you can see, with how many were added and how many expired today.Indicators
Feeds healthyHealthy feeds out of all your feeds, and how many are stale or failing. The dot is green when all are healthy, yellow when one is stale, and red when one is failing.Feeds
Detections liveDetection rules that are on, and how many run in shadow.Detections, filtered to rules that are on
ATT&CK coverageThe share of ATT&CK techniques used by threats relevant to you that have a live detection. Shows "—" until a threat has been scored as relevant.Coverage

A feed is stale when it hasn't succeeded for more than twice its polling interval (24 hours for bulk feeds). It is failing when its last run failed.

Cards​

Needs attention​

The things most worth a look, highest first. Items are ranked by indicator confidence, the value of the affected asset and how recent they are. Each item has a coloured dot for its severity (critical, high, medium or low) and links to where you can act on it.

ItemExample
An indicator seen in your environment"185.220.101.4 seen on 3 endpoints"
A known exploited vulnerability on software you own"KEV CVE-… on 14 owned hosts"
Hits from a retro-hunt"Retro-hunt: 2 hits for …"
A shadow rule that fires a lot"Rule … fired 212× in shadow"
A feed that is failingThe feed and its error

When there is nothing to flag, the card says "Nothing needs attention right now."

Threats relevant to you​

The three threats (actors, malware and campaigns) that overlap most with your stack, based on the products you have connected, the software you own and your detections. Each shows why it is relevant and one fact to act on: how many of its techniques you don't cover yet, how many of its CVEs you own, or "low overlap". Click a threat to open it on the Threats tab, or All threats to see the full list.

Feed health​

Your feeds, problems first. Each shows whether it is shared or private (and TAXII or MISP), how many indicators it adds per day, how many matches it produced this week and its largest overlap with another feed. A failing feed shows its error instead. The time on the right is its last successful run. Click a feed to open it on the Feeds tab.

Coverage​

A small ATT&CK map: one row per tactic, one square per technique. Darker squares have a live detection, lighter ones are covered only by hunts or shadow rules, and grey ones have no coverage. Under the map are the counts. Click Open coverage for the full map. See Coverage.

Coverage is measured per organization. If your scope is Personal, the card asks you to switch to an organization.

If a card can't load​

Each card loads on its own. If one fails, it shows the error and a Retry button, and the rest of the page keeps working.

Next steps​

  • Coverage — the full ATT&CK coverage map